News

CVE-2025-4123 Grafana

This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts Grafana. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.

Unauthorized PayPal Account Email - Phishing Email

We have received several reports of unrecognized, bogus PayPal account creation attempts using @berkeley.edu email addresses.

Drupal Core SQL Injection Vulnerability CVE-2026-9082

This is a follow-up to a notice alerting you to a critical vulnerability affecting sites running the Drupal Content Management System [1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this...

Drupal Core Vulnerability PSA-2026-05-18

ISO is aware of an upcoming critical security update that affects Drupal core. The Drupal Security Team has issued a heads-up (PSA-2026-05-18) about a highly critical security update coming out for Drupal core[1].

ISO Security Notice: NGINX Rift

ISO is aware of a critical vulnerability, codenamed NGINX Rift, that affects NGINX Plus and NGINX Open’s ngx_http_rewrite_module module, which is part of every standard NGINX build. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed...